Check: DTOO236 - Outlook
Microsoft Outlook 2007:
DTOO236 - Outlook
(in versions v4 r16 through v4 r15)
Title
All installed trusted COM addins can be trusted. (Cat II impact)
Discussion
All installed trusted COM addins can be trusted. Because the add-ins are controlled and known by the admins, they should always be presumed trusted.
Check Content
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security “Configure Add-In Trust Level” will be set to “Enabled (Trust all loaded and installed COM addins)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security Criteria: If the value AddinTrust is REG_DWORD = 1, this is not a finding.
Fix Text
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Security “Configure Add-In Trust Level” will be set to “Enabled (Trust all loaded and installed COM addins)”.
Additional Identifiers
Rule ID: SV-18671r1_rule
Vulnerability ID: V-17566
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |